发明名称 Distributed network connection policy management
摘要 <p>A connection policy for a communications network has a local connection policy indicating which paths between a given one of the nodes (computer A, router A, host 898) and others of the nodes (computers B, C, filters B1, B2, C1, C2, hosts 890, 892) are allowable paths, by a symbolic expression of ranges endpoint addresses and other local connection policies in respect of other nodes. It is implemented in a distributed manner by determining, for the given node, which of the allowable paths, are dual authorised as allowable by the other local connection policy relating to the other node at the other end of that path, by Boolean operations on the symbolic expressions. For a given message for a given path between two of the nodes having their own local connection policies, both of these nodes determine whether the given path is currently dual authorised. This can provide reassurance that changes in versions of the connection policy won't transiently open a risk of undetected unwanted communication.</p>
申请公布号 GB2459433(B) 申请公布日期 2012.06.06
申请号 GB20080004263 申请日期 2008.03.07
申请人 HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P. 发明人 ANTONIO LAIN;PATRICK GOLDSACK
分类号 H04L29/06;H04L12/24;H04L12/56 主分类号 H04L29/06
代理机构 代理人
主权项
地址